Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

December 3rd, 2012, 12:10 GMT · By

BLOG

WhatsApp Still Unsecure, Account Hijacking Possible Even After Updates

SHARE:

Adjust text size:


Experts warn that WhatsApp account hijacking is still possible Enlarge picture - Experts warn that WhatsApp account hijacking is still possible
Back in September, we learned that a flaw in WhatsApp, the popular cross-platform mobile messaging app, allowed cybercriminals to hijack user accounts. According to experts, these types of attacks are still possible, despite the fact that the company has recently made some changes.

Initially, the problem stemmed from the fact that the application used device IMEI numbers (on Android) and Wi-Fi interface MAC addresses (on iOS) to generate passwords.

Since these pieces of information can be obtained fairly simply, attackers could have easily hijacked accounts with the aid of the WhatsAPI PHP library, which has been specially adapted for this purpose.

After the updates made by WhatsApp, web clients that relied on the WhatsAPI library no longer worked. In theory, this meant that the issue was addressed, but the company didn’t provide any details regarding the changes it made.

However, The H reports that a user has provided security firm heise with a script that restored the WhatsAPI library to operation, implicitly re-enabling the attack method.

heise Security has offered to provide WhatsApp with all the details of the vulnerability, but the company’s representatives have failed to respond.

TELL US WHAT YOU THINK:

2,063 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Java JRE 7 Zero-Day Sold on Underground Market for Five-Digit Sum

Piwik.org Hacked, Attacker Adds Malicious Code to Installation Files

Crooks Leverage Flaw in Keycard Locks to Break Into Hotel Rooms

Go Daddy Resets Passwords of Customers Whose Sites Are Used to Spread Malware

Hacker Sells Yahoo! Mail Zero-Day for $700 (€550) – Video

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM